CVE-2020-11507 – Untrusted Search Path vulnerability in AdwCleaner

SUMMARY:

An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.

AFFECTED VERSIONS

  • Malwarebytes AdwCleaner 8.0.3

PATCHED VERSIONS

  • Malwarebytes AdwCleaner 8.0.4

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

CWECVS 3.xCVS  2Impact
CWE-426: Untrusted Search Path7.8 High6.9 MediumLocal